Impact
Missing Authorization in vowelweb Sirat allows exploitation of incorrectly configured access control security levels. The vulnerability can enable users who should not have access to perform actions that are normally restricted, potentially leading to unauthorized alterations or compromise of website integrity.
Affected Systems
The Sirat theme from vowelweb is affected. All releases from the earliest version through and including 1.5.1 are vulnerable. WordPress sites using any of these theme versions are at risk and should verify the theme version in use.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% implies a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through an unauthenticated or minimally privileged user crafting requests to theme-related operations that lack proper authorization checks. The potential impact is restricted to the functions exposed by the theme but could affect site content or configuration.
OpenCVE Enrichment
EUVD